Donate Now Goal amount for this year: 799 USD, Received: 100 USD (13%)
Please donate to help support this website. The funds will be used to purchase owned license of LiteSpeed Web Server Enterprise (2-CPU). It provides superior performance in terms of raw speed, scalability and anti-DDoS capabilities.

Results 1 to 2 of 2
  1. #1
    Righteous Dude
    Points: 23,243, Level: 93
    Level completed: 90%, Points required for next Level: 107
    Overall activity: 79.0%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    Aug 2009
    Posts
    1,597
    Liked
    523 times

    Internet Explorer Vulnerability And Temporary Fix

    Another Internet Explorer vulnerability was disclosed yesterday by Microsoft. All Internet Explorer versions from Internet Explorer 5.01 to 8 are affected on all Microsoft operating systems. A mitigating factor on Windows Vista and later operating systems (like Windows 7) prevents the exploitation of the vulnerability in Internet Explorer 7 and Internet Explorer 8 if protected mode is enabled in the web browser. Protected mode is enabled by default in those browsers.

    That leaves Windows XP as the main target of the vulnerability which can be used to read files from the operating system if the filename and path are known.


    The vulnerability exists due to content being forced to render incorrectly from local files in such a way that information can be exposed to malicious websites.


    At this time, we are unaware of any attacks attempting to use this vulnerability. We will continue to monitor the threat environment and update this advisory if this situation changes. On completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs.

    Microsoft provides access to four different temporary solutions to protect a computer system from the Internet Explorer vulnerability. Solution four is probably the easiest and most convenient solution at this moment.
    Set Internet and Local intranet security zone settings to “High” to prompt before running ActiveX Controls and Active Scripting in these zones

    To raise the browsing security level in Internet Explorer, follow these steps:

    1. On the Internet Explorer Tools menu, click Internet Options.
    2. In the Internet Options dialog box, click the Security tab, and then click the Internet icon.
    3. Under Security level for this zone, move the slider to High. This sets the security level for all Web sites you visit to High.

    Note If no slider is visible, click Default Level, and then move the slider to High.

    Note Setting the level to High may cause some Web sites to work incorrectly. If you have difficulty using a Web site after you change this setting, and you are sure the site is safe to use, you can add that site to your list of trusted sites. This will allow the site to work correctly even with the security setting set to High.
    Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone.

    To do this, follow these steps:

    1. In Internet Explorer, click Internet Options on the Tools menu.
    2. Click the Security tab.
    3. Click Internet, and then click Custom Level.
    4. Under Settings, in the Scripting section, under Active Scripting, click Prompt or Disable, and then click OK.
    5. Click Local intranet, and then click Custom Level.
    6. Under Settings, in the Scripting section, under Active Scripting, click Prompt or Disable, and then click OK.
    7. Click OK two times to return to Internet Explorer.

    Note Disabling Active Scripting in the Internet and Local intranet security zones may cause some Web sites to work incorrectly. If you have difficulty using a Web site after you change this setting, and you are sure the site is safe to use, you can add that site to your list of trusted sites. This will allow the site to work correctly.
    Enable Internet Explorer Network Protocol Lockdown for Windows XP

    To lockdown the “file” protocol, paste the following text in a text editor such as Notepad. Then, save the file by using the .reg file name extension.

    Windows Registry Editor Version 5.00
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]
    “explorer.exe”=dword:00000001
    “iexplore.exe”=dword:00000001
    “*”=dword:00000001

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\1]
    “file”=”file”

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\3]
    “file”=”file”

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols\4]
    “file”=”file”
    Enable Internet Explorer Network Protocol Lockdown using automated Microsoft Fix It

    http://support.microsoft.com/kb/980088

    System administrators can take a look at the vulnerability information page for further information about and impact of the vulnerability.

    http://www.ghacks.net/2010/02/04/int...temporary-fix/


    A Guy

  2. #2
    Loverboy
    Points: 57,861, Level: 100
    Level completed: 0%, Points required for next Level: 0
    Overall activity: 24.0%
    Achievements:
    31 days registered3 months registered1 year registeredTagger Second Class100 Experience Points

    Join Date
    Jul 2009
    Location
    Singapore
    Posts
    6,123
    Liked
    226 times
    This doesn't affect me as I've left IE Protected Mode on...and for those of you still using IE, I guess you should too...
    They call me the mysterious one...
    my motto is...when it's hot, chill baby

 

 

Similar Threads

  1. Replies: 13
    Last Post: 04-02-2010, 11:26 AM
  2. New Internet Explorer Vulnerability Confirmed
    By A Guy in forum Spyware/Viruses
    Replies: 4
    Last Post: 03-03-2010, 07:43 PM
  3. Internet Explorer 7
    By Patch in forum Software
    Replies: 5
    Last Post: 01-04-2010, 02:44 PM
  4. Internet Explorer 7 cannot run
    By epah_7 in forum Hardware
    Replies: 3
    Last Post: 09-23-2008, 10:04 PM
  5. Internet explorer 7
    By lilyoungsta in forum Software
    Replies: 6
    Last Post: 12-27-2006, 12:13 PM
All times are GMT +8. The time now is 09:45 PM.